forked from dataplat/dbatools
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathDisable-DbaDbEncryption.Tests.ps1
67 lines (62 loc) · 2.95 KB
/
Disable-DbaDbEncryption.Tests.ps1
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
$CommandName = $MyInvocation.MyCommand.Name.Replace(".Tests.ps1", "")
Write-Host -Object "Running $PSCommandpath" -ForegroundColor Cyan
. "$PSScriptRoot\constants.ps1"
Describe "$CommandName Unit Tests" -Tags "UnitTests" {
Context "Validate parameters" {
[object[]]$params = (Get-Command $CommandName).Parameters.Keys | Where-Object { $_ -notin ('whatif', 'confirm') }
[object[]]$knownParameters = 'SqlInstance', 'SqlCredential', 'Database', 'InputObject', 'EnableException', 'NoEncryptionKeyDrop'
$knownParameters += [System.Management.Automation.PSCmdlet]::CommonParameters
It "Should only contain our specific parameters" {
(@(Compare-Object -ReferenceObject ($knownParameters | Where-Object { $_ }) -DifferenceObject $params).Count ) | Should Be 0
}
}
}
Describe "$CommandName Integration Tests" -Tags "IntegrationTests" {
BeforeAll {
$PSDefaultParameterValues["*:Confirm"] = $false
$passwd = ConvertTo-SecureString "dbatools.IO" -AsPlainText -Force
$masterkey = Get-DbaDbMasterKey -SqlInstance $script:instance2 -Database master
if (-not $masterkey) {
$delmasterkey = $true
$masterkey = New-DbaServiceMasterKey -SqlInstance $script:instance2 -SecurePassword $passwd
}
$mastercert = Get-DbaDbCertificate -SqlInstance $script:instance2 -Database master | Where-Object Name -notmatch "##" | Select-Object -First 1
if (-not $mastercert) {
$delmastercert = $true
$mastercert = New-DbaDbCertificate -SqlInstance $script:instance2
}
$db = New-DbaDatabase -SqlInstance $script:instance2
$db | New-DbaDbMasterKey -SecurePassword $passwd
$db | New-DbaDbCertificate
$db | New-DbaDbEncryptionKey -Force
$db | Enable-DbaDbEncryption -EncryptorName $mastercert.Name -Force
}
AfterAll {
if ($db) {
$db | Remove-DbaDatabase
}
if ($delmastercert) {
$mastercert | Remove-DbaDbCertificate
}
if ($delmasterkey) {
$masterkey | Remove-DbaDbMasterKey
}
}
Context "Command actually works" {
It "should disable encryption on a database with piping" {
# Give it time to finish encrypting or it'll error
Start-Sleep 10
$results = $db | Disable-DbaDbEncryption -NoEncryptionKeyDrop -WarningVariable warn
$warn | Should -Be $null
$results.EncryptionEnabled | Should -Be $false
}
It "should disable encryption on a database" {
$null = $db | Enable-DbaDbEncryption -EncryptorName $mastercert.Name -Force
# Give it time to finish encrypting or it'll error
Start-Sleep 10
$results = Disable-DbaDbEncryption -SqlInstance $script:instance2 -Database $db.Name -WarningVariable warn
$warn | Should -Be $null
$results.EncryptionEnabled | Should -Be $false
}
}
}